Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in CRM-BF-IIA, SAP security note 1874456

SAP Note 1874456
SAP Security Note

SAP security note 1874456, "Directory traversal in CRM-BF-IIA", released on August 13, 2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Basic Functions > Interactive Intelligent Agent (CRM-BF-IIA)
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onAugust 13, 2013
LanguageEnglish

Description

Symptom

CRM-BF-IIA contains a vulnerability that allows an attacker to perform directory traversal. This can potentially enable the attacker to read arbitrary files on the remote server, leading to the disclosure of confidential information.

Solution

Refer to SAP Note 1497003 for additional information and instructions. Corrections from that note are a prerequisite for implementing this note.

CVSS

Score 0

References

Affected components

  • Customer Relationship Management > Basic Functions > Interactive Intelligent Agent (CRM-BF-IIA)
  • Customer Relationship Management > Interaction Center WebClient > Knowledge Search (CRM-IC-SOL)

Full note on SAP: SAP Support Launchpad note 1874456

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More